Infosecurity-Magazine
HollowFrame Loader and Matryoshka Malware Target Law Firm with Advanced Techniques
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A sophisticated cyberattack has been identified, targeting a law firm with a new Go-based loader named HollowFrame and a Rust-based malware family called Matryoshka. The attack commenced with a spear-phishing email leading to an encrypted archive containing a malicious Windows Shortcut file. Upon execution, the malware escalated privileges, disabled Microsoft Defender protections, and downloaded additional payloads. HollowFrame employs DLL sideloading techniques using a counterfeit Python runtime to evade detection. The Matryoshka backdoor features two variants, one utilizing HTTP and the other leveraging a private GitHub repository for command and control. The attack's modular design complicates detection and attribution, posing a significant threat to the affected organization. Blackpoint Cyber has recommended monitoring for unexpected GitHub API connections as part of their mitigation strategy.
Key Points: • The HollowFrame loader uses a fake Python DLL to bypass Microsoft Defender. • The attack targets a law firm, employing spear-phishing to initiate the intrusion. • Matryoshka malware features two variants, complicating detection and enhancing persistence.